CommitCAUTION
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Overview
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
d90170da4369OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: commit description: Generate a conventional commit message for staged changes argument-hint: "[--amend] [message]" effort: low when_to_use: "Use when ready to commit staged changes and need a conventional commit message." disable-model-invocation: true --- # Conventional commit Generate a conventional commit message for staged changes. ## Instructions 1. Run `git diff --cached` to see staged changes 2. Analyze the nature of changes 3. Generate a commit message following the format below ## Commit format ``` <type>(<scope>): <subject> [optional body] [optional footer] ``` ### Types - `feat`: New feature - `fix`: Bug fix - `docs`: Documentation only - `style`: Formatting, missing semicolons, etc. - `refactor`: Code change that neither fixes nor adds feature - `perf`: Performance improvement - `test`: Adding missing tests - `chore`: Maintenance tasks ### Rules - Subject: imperative mood, no period, max 50 chars - Body: explain WHAT and WHY, not HOW - Footer: breaking changes, issue references ## Examples ``` feat(auth): add password reset functionality Implement password reset flow with email verification. Users can now request a reset link and set new password. Closes #123 ``` ``` fix(api): prevent race condition in order processing Add mutex lock to ensure orders are processed sequentially. This fixes duplicate charge issues reported by users. Fixes #456 ``` ``` refactor(cart): extract pricing logic to separate module No functional changes. Improves testability and separates concerns for future discount feature. ``` ## Execution After analyzing staged changes, suggest a commit message. Ask for confirmation before executing `git commit -m "..."`. $ARGUMENTS
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
whitepapers/recap-cards/en/_extensions
whitepapers/recap-cards/fr/_extensions
Gates applied: no_behavioural_pass.
d90170da4369full audit observations/trust-audit/skill/florianbruniaux__commit.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d90170da4369 | CAUTION | B | 89 | first audit |
Questions
What does the Commit skill do?
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Is Commit safe to install?
With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Commit access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (d90170da4369), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.